0xffchain

513 posts

0xffchain banner
0xffchain

0xffchain

@0xffchain

Engr | SR | Focus: vaults | SR @sigp_io | Ex @secure3io, @LeastAuthority, @odyssey_dao

Katılım Şubat 2022
279 Takip Edilen128 Takipçiler
0xffchain
0xffchain@0xffchain·
@ScrewCopper @bytes032 @oot2k1 There is no more obvious training ground for new SR‘s. So when next there is a high and the market demand for SR naturally increases, existing SR will be in high demand , as there are less new entrants compared to before .
English
0
0
1
27
0xffchain
0xffchain@0xffchain·
@MitchellAmador Could you explain more on the ai fad? How did SRs abandon the space to chase that
English
1
0
0
40
Mitchell Amador
Mitchell Amador@MitchellAmador·
It's been almost a year since I wrote this, and blocksec has changed a tonne. Have things become better or worse for security researchers? I feel like we were able to prevent some of these (Immunefi continues to pay millions in bounties monthly) but things feel much rougher. And some players abandoned their SRs entirely to chase the AI fad. We need to understand what went wrong to make 2026 the whitehat summer we're all hoping for.
Mitchell Amador@MitchellAmador

x.com/i/article/1940…

English
4
4
37
3.4K
0xffchain
0xffchain@0xffchain·
After I am done understanding what the report is about, I go back to the original finding... I read the finding to make sure I am not missing any meat, and to also absolve as much as I can of the context and feed my eyes with the pattern so its easier to catch on sight.
English
0
0
0
8
0xffchain
0xffchain@0xffchain·
AI helping alot with digesting reports. But you can miss alot if you is primarily AI to read a report alone. My workflow is: I feed the report to AI to get the hang of whats its talking about, and it summarizes it with an existing framework.
English
1
0
0
7
David Wong
David Wong@cryptodavidw·
I feel like AI has taken a lot of my drive to write. I used to LOVE writing so much, as one can attest from my blog. Since LLMs have become so good at writing it feels so pointless to write. It's not so special anymore. You don't stand out. Worse, AI writes better than me. What's the point anymore? I understand Lee Sedol.
English
23
1
39
5.1K
0xffchain
0xffchain@0xffchain·
Any day I don't follow my routine I feel weird. Thats cool. Exercise + breathwork, breathwork + meditation and off the conquer the day...
English
0
0
0
13
0xffchain
0xffchain@0xffchain·
Pomodoro leaves me exhausted when I complete my sessions, and also gives this level of satisfaction knowing you accomplished something for the day.
English
0
0
0
13
0xffchain
0xffchain@0xffchain·
My goal for the coming months is perfecting my routine. Pomodoro is back on board baby...
English
2
0
0
98
Emmanuel
Emmanuel@emmanuelSR77·
- April 2027. $1M audit contest. - SRs unleash their god-tier AIs to hunt vulns (Mythos is the weakest tool in the arena). - Bob finds a bug through manual audit. - Contest ends. 23 unique vulns found. 22 of them have 20+ duplicates each. - Bob takes $950K.
English
8
2
104
7.4K
sudo rm -rf --no-preserve-root /
rant time: people are so fucking obsessed with building more tools, more products, more services, more "security" layers. are you guys all fucking insane?? every single thing you add is more complexity. and complexity is exactly what makes systems _dangerous_. you don't get safer by stacking abstractions on top of abstractions. you just increase the attack surface and pray the whole dependency chain doesn't collapse (hint: it will collapse!!). now you depend on 10, 50, 100 moving parts. all needing updates, all with their own bugs, all potential supply chain failures and we call that "security" like fucking retards. dude, it's the fucking opposite. we're not building safer systems. we're building systems so complex nobody actually understands them anymore. and almost nobody is asking the obvious question: **what can we remove?** everyone wants to add. nobody wants to reduce. that's how you end up in a nightmare system (hint: we're already in that nightmare). not because of one big failure. but because of thousands of tiny dependencies you never should have had in the first place.
English
34
27
246
12.7K
0xffchain
0xffchain@0xffchain·
Once you understand the data architecture of the application you working on, you half understood the application already, most of the logic is just manipulating that data in interesting ways.
English
0
0
0
14
0xffchain
0xffchain@0xffchain·
Cause I believe in this time, regardless of what you work on, AI is already a factor. So understanding it deeply should be a force multiplier.
English
0
0
0
9
0xffchain
0xffchain@0xffchain·
I have been thinking of what to work on, on my spare time. Like a weekend project, but I am yet to find. Maybe work on understanding how LLM's actually work under the hood?
English
1
0
0
26
0xffchain
0xffchain@0xffchain·
@banteg What of 0/1? common that cant get hacked.
English
0
0
0
225
banteg
banteg@banteg·
guys don't tell me your answer to 1/1 multisigs getting hacked is 2/2 multisigs. sometimes i feel this industry is incapable of learning.
English
57
67
829
57.7K
0xffchain
0xffchain@0xffchain·
@4gontuk No connection between the contest kinda model and most of the recent hacks.
English
0
0
0
17
Agontuk 🏴‍☠️
Agontuk 🏴‍☠️@4gontuk·
Public audit contests have dropped massively over the past few months, while multi-million dollar hacks have surged. We’ve already seen several major incidents in 2026. Coincidence… or something more?
English
5
3
59
2.6K
shafu
shafu@shafu0x·
make defi dumb again
English
18
5
106
3.6K
0xffchain
0xffchain@0xffchain·
What makes LLM's so good at helping with other vectors that are less reviewed or have less SR talents?
English
0
0
0
23
Alex the Entreprenerd
Alex the Entreprenerd@GalloDaSballo·
What other vectors are being constantly underestimated and will lead to more massive exploits?
English
6
1
10
1.7K